{"id":2828,"date":"2021-10-10T14:47:01","date_gmt":"2021-10-10T09:17:01","guid":{"rendered":"https:\/\/www.amitacare.com\/?page_id=2828"},"modified":"2021-10-10T15:11:44","modified_gmt":"2021-10-10T09:41:44","slug":"privacy-policy-3","status":"publish","type":"page","link":"https:\/\/amitacare.com\/index.php\/privacy-policy-3\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"2828\" class=\"elementor elementor-2828\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ff299f1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ff299f1\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-ae661f9\" data-id=\"ae661f9\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c55a8e3 elementor-widget elementor-widget-spacer\" data-id=\"c55a8e3\" data-element_type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e98ccd7 elementor-widget elementor-widget-heading\" data-id=\"e98ccd7\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Data and Personal Privacy Policy<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-e8d3a21 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"e8d3a21\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-63b0c1f\" data-id=\"63b0c1f\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9315183 elementor-widget elementor-widget-text-editor\" data-id=\"9315183\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p><br>We, at AMITA, are committed to ensuring and protecting the personal information and data<br>privacy of our visitors 1 , user of services 2 and practitioners 3 on our web portal, social media<br>and other forms of media. AMITA is a software application for service promoted by<br>PEARLSS 4 Development Private Limited and this Privacy Policy applies to digital, social and<br>software applications and provided by AMITA, not just limited to this website. This Privacy<br>Policy is our sincere effort to document and explain to the user, visitor and practitioner on<br>the manner on how we are, and the reasons for, collecting, defining, protecting, utilising and<br>disclosing personal information shared by the user, visitor and practitioner during the<br>process of exploring and\/or using our services. It is our utmost endeavour to guarantee<br>accurate information and services of integrity and quality and hence, we take greatest care<br>when publishing our data, photographs, graphics, videos and messages.<br>We have used a simple, clear, concise and easily understandable language. Whenever<br>necessary, we will have the Privacy Policy in languages other than English. This policy will<br>be read along with the \u2018terms for use of services\u2019 and the \u2018practitioner terms for practice\u2019 and<br>will apply to the services owned and operated by AMITA. The policy does not vouch for the<br>privacy of other services, such as advertisements or searches run by third party providers on<br>our web portal or the social media and hence, we bring this to the user\u2019s, visitors and<br>practitioners\u2019 consideration that they explore the web portal, social media and other forms of<br>media with their independent judgement assessing the risks involved. We have tried to be as<br>informed as possible on the needs and the legal considerations while framing this policy.<br>The purpose of the Privacy and Data Protection Policy is:<br>i. To maintain maximum level of professionalism assuring high levels of privacy and<br>safety of the user data<br>ii. To describe and establish procedures for expressed consent and delimit purpose for<br>data protection and privacy<br>iii. To elucidate the safeguards and code of practice in data processing, storage of data,<br>and user data protection<br>iv. To lay down the obligations and the considerations taken within the legal<br>requirements and regulatory compliances<br>v. To confer the rights of the user to obtain data, correct inaccuracies, erase, update,<br>port to other fiduciaries and restrict\/prevent disclosure of personal data<br>vi. To inform users on the institutional instruments of AMITA for data protection,<br>consent, grievance and fiduciary for protecting user interest, misuse of data,<br>compliance and promoting awareness on safety including intermediaries for social<br>media.<br>vii. To institutionalise proper recording procedures ensuring adequate procedures and<br>process for data protection and privacy.<br>Legal instruments governing the Privacy Policy<br>This Privacy Policy is governed under the following Acts and in compliance with:<\/p>\n<p>i. Personal Data Protection&nbsp;Act&nbsp;2019 (PDPA, 2019)<br>ii. Information Technology Act, 2000<br>a. Section 43A of the Information Technology Act, 2000;<br>b. Regulation 4 of the Information Technology (Reasonable Security Practices<br>and Procedures and Sensitive Personal Information) Rules, 2011 (the \u201cSPI<br>Rules\u201d);<br>c. Regulation 3(1) of the Information Technology (Intermediaries Guidelines)<br>Rules, 2011.<\/p>\n<p>Consenting to providing personal data<br>When any user visits the website, social media pages or seeks therapy services, s\/he will<br>leave behind some footprints. When the user seeks services and marks her acceptance on<br>the consent form, s\/he enters into a contractual agreement to receive services as laid down<br>in the section 14 of the Indian Contract Act, 1872. The user is expected to read the consent<br>form and \u2018tick\u2019 inside the box, to demonstrate that s\/he is willing to share personal details<br>and to ascent to the processing of sensitive personal data for the purposes listed in sub-<br>section 1, clause 3(36) in PDPA Act 2019 and to draw inferences from the anonymised data.<br>The users\u2019 consent to the services is based on premise that s\/he has read this privacy and<br>other policy documents provided on the website. Through the acceptance of the consent<br>form, the user, visitor and practitioner affirm that s\/he is exploring or using the platforms<br>such as website, social media and therapy services out of her\/ his free will and has got a<br>clear and adequate information on the specific privacy considerations with regards to their<br>use.<br>We pre-suppose that user, visitor and practitioner has read the privacy policy before<br>exploring the platform and consent to the terms and conditions of the privacy policy, terms<br>of use and the practitioner before one decides to become a stakeholder of AMITA. The<br>policy is binding and hence everyone who is using the website will need to read it. We<br>assure that the data will be used only for the purposes consented by the user or that is<br>incidental or connected with the purpose and will be used for purposes that the user will<br>reasonably expect with regard to the purpose and in the context and circumstances in which<br>the personal data was collected. We have tried to be as informed as possible on the needs<br>and the legal considerations while framing this policy.<br>The user, visitor and practitioner acknowledge that one has read through this document and<br>abides by the Privacy policy:<br>i. That the type of data collected contains Personal Information (under the PDPA Sec 2,<br>3(28) and Sensitive Personal data (Sub-section 1, clause 11(3)) related to the user<br>and his\/her family<br>ii. That the personal data:<br>a. is collected under fair, informed and reasonable contexts and circumstances<br>b. has ensured the users\u2019 and family privacy<br>c. can be used, as agreed upon in this privacy policy, for purpose of<br>a. Processing data<br>b. Retaining data<br>c. Destroying data<br>d. Disclosing data<\/p>\n<p>We use a layered approach for consent for our therapy session to facilitate informed<br>decisions. There is a consent taken for recording of the therapy sessions too. When the<\/p>\n<p>user or therapist records the session from his\/her end, s\/he needs to take permission from<br>the therapist\/user. The Consent Manager for the psychotherapy sessions will be the user\u2019s<br>therapist. Just in case the user wishes to have some additional privacy terms, s\/he has a<br>choice to separately consent for each of the features, such as the purposes of, operations in,<br>the use of different categories of sensitive personal data relevant to processing and so on<br>by writing an email to the official contact address \u2018admin@amitacare.com\u2019. The user will<br>receive redressal email from the AMITA informing about the changes made.<br>Withdrawal of consent<br>During the process, the user has the right to withdraw the consent with ease for whatsoever<br>reason and s\/he will not be compelled to continue the therapy sessions. The reasons for<br>withdrawal of consent, when the user has previously consented, need to be clearly<br>mentioned. The user will need to send an email to the official address<br>\u2018admin@amitacare.com\u2019 and s\/he will receive an acknowledgment for the same. S\/he<br>should be able to resolve the same within a few days as laid down by the regulations. When<br>the user withdraws the consent from the processing of any personal data without any valid<br>reason, there may be legal consequences for the effects of such withdrawal. If for any<br>purpose or reason for withdrawal of consent is not aligned with the regulations, the user will<br>have to bear the costs of the legal procedures.<br>Consent for children<br>Children are considered as those below the age of 18 years according to the Juvenile<br>Justice Act, 2015 (Care and Protection of Children). When the user seeks services as an<br>authorised authority for another person who is a child under the definition of Juvenile<br>Justice Act 2015 (Care and Protection of Children) or incapacitated to provide consent<br>under the Indian Contract Act, 1872, the user will be whole and sole responsible for acting on<br>the best interest on behalf of that person. When children seek services, the parents or the<br>adult guardian of the child will provide the consent to the services, while, the assent will be<br>taken from the children. We will make efforts to talk to the child to involve the parents in the<br>therapeutic process in context where the child is not willing to involve parents. However, the<br>older children especially adolescent may seek services on their own and making it<br>mandatory for them to involve parents may be counterproductive to promoting teenagers to<br>approach services. Hence, we will need to further deliberate with the Internal Ethics<br>Committee to draw guidelines for ethics, including issues related to tele-psychotherapy and<br>data protection for teenage children. This is in line with the PDPA 2019, where we as<br>guardian data fiduciary as providers of providing exclusive counselling services to a child,<br>we shall not require to obtain the consent of parent or guardian of the child under sub-<br>section 2 \u2018Obligations of Data Fiduciary\u2019 of the PDPA Act.<br>Nature and categories of Personal details captured<br>Any service or service improvement starts with knowing the client and the clients\u2019 needs. It<br>is our sincere effort and desire that the user understands personal data and associate<br>terminology adequately. The information that we collect will only be to the extent that is<br>necessary for the processing of such personal data that is required for our therapeutic<br>services. As we collect the data, we need the user to understand some terms of relevance<br>covered under the PDPA&nbsp;2019:<br>a. Personal data means data about or relating to a natural person who is directly or<br>indirectly identifiable, having regard to any characteristic, trait, attribute or any other<br>feature of the identity of such natural person, whether online or offline, or any<\/p>\n<p>combination of such features with any other information, and shall include any<br>inference drawn from such data for the purpose of profiling.<br>b. Sensitive Personal Data or Information of a person means personal information<br>about that person relating to, passwords; financial information such as bank<br>accounts, credit and debit card details or other payment instrument details; physical,<br>physiological and mental health condition; sexual orientation; medical records and<br>history; biometric information; information received by body corporate under lawful<br>contract or otherwise; visitor details as provided at the time of registration or<br>thereafter; and call data records.<br>c. Genetic data means personal data relating to the inherited or acquired genetic<br>characteristics of a natural person which give unique information about the<br>behavioural characteristics, physiology or the health of that natural person and which<br>result, in particular, from an analysis of a biological sample from the natural person<br>in question.<br>d. Health data means the data related to the state of physical or mental health of the<br>data principal and includes records regarding the past, present or future state of the<br>health of such data principal, data collected in the course of registration for, or<br>provision of health services, data associating the data principal to the provision of<br>specific health services.<br>Any user registering to our psychotherapy and mental health interventions will be required to<br>provide all the four categories of information. When the user desires to use our<br>psychotherapy and mental health services, we will ask for the name, contact details and<br>basic personal details as identifiers before they register and engage in therapy. This will<br>help the psychotherapist to be prepared for a session with the user. We take user email ID<br>to send an email and the user will open the email using the password. In addition, the user<br>will be asked to enter his\/her users\u2019 mobile number and some basic data. This number is<br>primarily to contact the user in need and will not be used for marketing purposes or to push<br>messages. The user can opt for \u2018do not call registry\u2019, a clause available under the PDPA<br>2019 by a clear, unambiguous expressed written communication ascertain non-consent to<br>receive mobile\/telephone calls\/push emails.<br>When the user starts the psychotherapy session with the psychotherapist, s\/he will once<br>again explain the consent form. S\/he will ask the user about personal and demographic<br>details, problems, personal and family details. S\/he will also collect information on the user<br>and family mental health condition, sexual orientation, medical records and history, to name<br>a few. S\/he will need to know them so that s\/he can diagnose the problem and then plan<br>and provide an intervention that matches the various dimensions of the problem, personality,<br>family conditions and cultural realities using the theoretical frameworks for intervention.<br>The other points where personal information is shared include:<br>i. The user may also send an email or contact AMITA over phone or email and<br>share some personal information at that time.<br>ii. When the user makes payments, the financial information such as bank<br>accounts, credit and debit card details or other payment instrument details will be<br>used.<br>iii. The user may have personal information on public domains and we may decide<br>to collate free to use data from the public domain. For such information available<br>on the public domain, we will be using it without going through the process of<br>consent for disclosing information<\/p>\n<p>iv. Visitors on the website leave a footprint on the web which we may choose to<br>track and gain understanding on the people who are visiting the website,<br>selecting the service or exploring the website.<\/p>\n<p>Purposes for collecting data<br>The data collected will be used, but not exclusive, for the following purposes:<br>i. To provide the user mental health interventions and psychotherapy and maintain<br>electronic recording systems that meets the best standards for professional practice<br>and as consented by user<br>ii. To institute a well-planned and recorded need-based referral service system for users<br>of AMITA services<br>iii. To generate reports on psychological tests, evaluations, certificates and<br>recommendations to be shared, submitted or provided on behalf of users. It may for<br>self, workplaces, insurance organisations etc.<br>iv. For issuance of any certificate, licence or permit for any action, activity or<br>provisioning under the State or otherwise as requested by user<br>v. To contact user in need especially in special circumstances, such as incomplete<br>registration, follow up or grievance management.<br>vi. To provide analytic perspective to inform the team on the patterns of individual and<br>group presentation of users and the symptomatology using analysis of anonymised<br>data<br>vii. To respond to any medical emergency involving a threat to the life or a severe threat<br>to user\u2019s health<br>viii. To undertake any measure to provide medical treatment or health services to the<br>user or community with psychiatric disorders using anonymised data during an<br>epidemic, outbreak of disease or any other threat to public health; or<br>ix. To undertake measures that ensure the safety of, or provide assistance to or services<br>to, any individual during any disaster or any breakdown of public order.<br>x. To track and improvise efficiency and efficacy of interventions, appointment booking<br>systems, ascertain customer satisfaction trends and practitioner practice patterns<br>xi. For research, analysis and business intelligence using anonymised data published as<br>research reports, published articles and newsletters.<br>xii. To meet routine and other legal or regulatory compliance including those arising out<br>of any order or judgement of any Court or Tribunal in India<br>xiii. To generate data to advocate with the State on behalf of user needs under any<br>law\/program<br>xiv. To assist in the billing and accounting processes<br>xv. For performance improvement or problem solving of information systems, for e.g.,<br>debugging exercise<br>xvi. To publish anonymised data on website, social media and annual\/monthly reports,<br>especially client feedback<br>a. For promoting and publish and studying customer feedback on new and existing<br>products and services<br>b. For product and software improvement on design and utility<br>c. For payment purposes including third party payment gateways and service providers<br>such as banks, financial institutions etc.<br>Accuracy of data<\/p>\n<p>It is the user\u2019s responsibility to provide accurate information on the contact details and<br>background details related to the problem in concern. The capturing of the therapy<br>information is carried out by the therapist in good faith and hence the responsibility is<br>shared between the user and the therapist as the situation may be. The user will have<br>access to review and correct, delete, modify or amend the information that is stored by<br>AMITA. In case the data that is capture or modified is not true, complete or out of date, we<br>will not be held responsible for it. When the data provided by users has legal or regulatory<br>issues due to incomplete and wrong information provided, we may have the sole discretion<br>to make decisions using the reasonable grounds and terminate services. We will also have<br>the discretion not to make the changes suggested by the user and when that happens, we<br>will communicate the same with the user in response to request made.<br>Confidentiality and shared confidentiality<br>The user\u2019s data will be known to his\/her psychotherapist. The data may also be overseen by<br>the admin, IT personnel, supervisory mental health professionals, institutional bodies for<br>privacy, safety and ethics, and research personnel as need basis to carry out the processes<br>we have elucidate as part of the purposes. Some part of the information may be accessible<br>by a few employees, agents or partners and third parties on a need-based basis. When these<br>confidentiality limits are expanded, we will bind them through robust contractual agreements<br>that bind them and their employees with strict confidentiality obligations. At times, we hold<br>case conferences where we may discuss the user case details or conference presentations<br>and research papers for localised or wider dissemination and learning for the goal of<br>enhancing skill sets of the therapist or other professionals.<br>A major responsibility at our end is to get both internal and external persons\u2019 having access<br>to the user personal data following the regulatory and ethical responsibility towards his\/her<br>personal data. We are committed to this and will build mechanisms for expanding know-<br>how on rights of the user and the standards and the safety mechanisms.<br>We, however, wish to draw the limits of our responsibility and inform the user that anything<br>beyond the scope of this privacy document will not be addressed by us. We will not be held<br>responsible for the breach of security or for any actions of the third-party arrangements that<br>are beyond our reasonable control, including but not limited to, acts of government,<br>computer hacking, unauthorised access to computer data and storage device, computer<br>crashes, breach of security and encryption, poor quality of Internet service or telephone<br>service providers of the User etc.<br>We also wish to inform the user, visitor and practitioner that the legal rights of the processed<br>personal information and data will rest with AMITA and no user, visitor or practitioner will<br>hold any right over it.<br>Preservation of personal data<br>Under the PDPA&nbsp;2019, the &amp;quot;official identifier&amp;quot; means any number, code, or other identifier,<br>assigned to a data principal under a law made by Parliament or any State Legislature which<br>may be used for the purpose of verifying the identity of a data principal (user). The user\u2019s<br>personal data will be preserved in a form that distinguishes personal data based on facts<br>from personal data based on opinions or personal assessments. Every user of<br>psychotherapy and mental health interventions registering for our services will be provided a<br>number for identification.<\/p>\n<p>Data processing<br>There are some terms that may be of important to know before the user understands the<br>privacy considerations in data processing and analysis<br>i. &amp;quot;Profiling&amp;quot; means any form of processing of personal data that analyses or predicts<br>aspects concerning the behaviour, attributes or interests of a data principal (user);<br>ii. \u201cProcessing&amp;quot; in relation to personal data, according to the Personal Data<br>Protection&nbsp;Act&nbsp;2019, means an operation or set of operations performed on personal<br>data, and may include operations such as collection, recording, organisation,<br>structuring, storage, adaptation, alteration, retrieval, use, alignment or combination,<br>indexing, disclosure by transmission, dissemination or otherwise making available,<br>restriction, erasure or destruction. The &amp;quot;data processor&amp;quot; means any person, including<br>the State, a company, any juristic entity or any individual, who processes personal<br>data on behalf of a data fiduciary (AMITA).<br>iii. &amp;quot;Significant harm&amp;quot; means harm that has an aggravated effect having regard to the<br>nature of the personal data being processed, the impact, continuity, persistence or<br>irreversibility of the harm. Some of the harm mentioned by the Personal Data<br>Protection&nbsp;Act&nbsp;2019 include, bodily or mental injury; loss of reputation or humiliation;<br>loss of employment; any discriminatory treatment; any denial or withdrawal of a<br>service, benefit or good resulting from an evaluative decision about the data principal<br>(user); any restriction placed or suffered directly or indirectly on speech, movement<br>or any other action arising out of a fear of being observed or under surveillance; any<br>observation or surveillance that is not reasonably expected by the data principal.<br>These terms have applicability in our operations and data management systems. Our effort<br>is to minimise and reduce the consequences of significant harms if any. The user needs to<br>understand how we might process the data. As the processing of personal data may be for<br>research, archiving and statistical purposes, the PDPA 2019 recognises that the compliance<br>with the provisions of this Act shall disproportionately divert resources from such purpose.<br>For archiving, anonymising data may not serve the purposes of processing and hence de-<br>identification in accordance with the code of practice specified under Code of Practice (Sub<br>-section 9, Clause 50) and the processing can be achieved if the personal data is in de-<br>identified form. Any personal data that is not being sensitive personal data may be<br>processed for &amp;quot;reasonable purposes&amp;quot; that may include but not exhaustive, whistle blowing;<br>network and information security; processing of publicly available personal data; and the<br>operation of search engines.<br>The personal data will not be used to take any decision specific to or action directed to the<br>user or other users. The personal data will not be processed in a manner that puts user to a<br>risk of significant harm to self or others. The PDPA 2019 exempts research, archiving, or<br>statistical purposes from the application of any of the provisions of the Act and the specified<br>regulations.<br>We shall take necessary steps to ensure that the personal data processed is complete,<br>accurate, not misleading and updated; having regard to the purpose for which it is<br>processed. If any data information or data processing involves cross-border transfer of the<br>personal data, it will be carried out as per the legal instruments of the government and in<br>such situations, the user will be informed on the same through an email on the registered<br>email ID.<\/p>\n<p>Our online services are not intentionally targeted to children but there is possibility that<br>children may explore our web portal and reach out for services. When we process personal<br>data of children, it will be assured that the rights of the child are protected and every action<br>is in the best interest of the child. In situations where the child needs services but for<br>whatever reasons the parental permissions are difficult to ascertain, we will be considering<br>seeking support from our Internal Ethics Committee to make decisions on provisioning on<br>the necessary support to continue the services to the child who most need them. This is in<br>line with the PDPA 2019, where we as guardian data fiduciary as providers of providing<br>exclusive counselling services to a child, we shall not require to obtain the consent of parent<br>or guardian of the child under sub-section 2 \u2018Obligations of Data Fiduciary\u2019 (AMITA) of the<br>PDPA Act.<br>Before processing of any personal data of a child, we will verify his\/her\/ age and obtain the<br>consent of his parent or guardian, in such manner as may be specified by regulations. The<br>PDPA 2019 suggests the following considerations for verification of the age of the child; the<br>volume of personal data processed; the proportion of such personal data likely to be that of<br>child; possibility of harm to child arising out of processing of personal data; and such other<br>factors as may be prescribed. We shall make all efforts to ensure that we do not profile,<br>track or behaviourally monitor of, or targeted advertising directly at children, especially those<br>that can cause significant harm to the child (Sub-section 4, clause 16(5) of the PDPA 2019).<br>Period of retaining personal data<br>The personal data considered for the process will not be retained beyond the period<br>necessary to satisfy the purpose for which it is collected unless and until it is necessary to<br>comply with any obligation under any law for the time being in force. When the data is<br>disclosed for the purpose of processing, it shall be deleted at the end of the processing by<br>ourselves and\/or by the process intermediaries. In certain circumstances, the personal data<br>in our possession may be required to be retained for a longer period for the purpose of<br>processing. We will undertake periodic review to determine whether it is necessary to retain<br>the personal data in our possession. In such circumstances, we will review the purpose for<br>which we collected and that we need to retain the data and come to a realistic determination<br>on the time period for which we need to retain the data. Once this purpose is met, we are<br>expected to securely delete user information when user data is no longer need for the<br>purpose; this is a little difficult to follow with therapy linked data as we do not know when<br>the user may reach to use the services once again. When personal data is deleted, it shall be<br>done as specified by regulations under the Act. When there is a change of terms for<br>retaining or on the security of the data, we will keep the user updated through intimation on<br>the website. The user will be informed in case the processing is not for the said purpose the<br>user has agreed under the consent ascertained.<br>Rights of the user<br>The PDPA 2019 provides rights for the user and this includes right to obtain from the data<br>fiduciary (AMITA)<br>i. confirmation whether the data fiduciary (AMITA) is processing or has processed<br>personal data of the data principal (user);<br>ii. the personal data of the data principal (user) being processed or that has been<br>processed by the data fiduciary (AMITA), or any summary thereof;<\/p>\n<p>iii. a brief summary of processing activities undertaken by the data fiduciary (AMITA)<br>with respect to the personal data of the data principal (user), including any<br>information provided in the notice under section 7 in relation to such processing.<br>In addition, the user has specifically the following rights, subject to such conditions and<br>specified by the regulations:<br>i. Access to personal data: The user has the right to ask us a copy of the personal data<br>that was provided by him\/her. The user also has the right to ask and review the<br>nature of the data we possess and how we intend to use it. In an eventuality we<br>refuse to respond, the user has the right to ask us the reason on why we have<br>refused to share the data and get a reply on the reasons for refusal.<br>ii. Correction of incomplete and misleading data or updation: The user has the right to<br>ask for the correction amendment or updation of the incomplete\/errored\/out of date<br>data.<br>iii. Deletion of data: The user has the right to request for deletion of data on certain<br>grounds. The reasons may include, the data is no longer serving the purposes of the<br>consent provided, infringements on the right of the user or has other legal<br>requirements that mandate the deletion of the data. The user may have to bear the<br>costs in any legalities emerge as part of the process. We may decide to inform the<br>persons associated with providing the data on the changes made in case the<br>changes are asked by persons\u2019 other than the user.<br>iv. Object or restrict data processing: The user has the right to object or restrict the<br>processing of the user\u2019s personal data in parts or as a whole<br>v. Consent: The user has the right to withdraw consent at any time during the course of<br>the engagement with valid reasons through communication over an email and<br>receive a response to that effect; including the reasons why the request could be<br>entertained. The consent for using processed data can be applicable to whole data<br>or parts of the data.<br>vi. Disclosure of data: The user has the right to restrict or prevent the continuing<br>disclosure of personal data and that may be enforced only on an order of the<br>Adjudicating Officer made on an application filed by user on the grounds that the<br>right or interest in preventing or restricting the continued disclosure of personal data<br>overrides the right to freedom of speech and expression and the right to information<br>of any other citizen, where such disclosure:<br>a. has served the purpose for which it was collected or is no longer necessary for the<br>purpose;<br>b. was made with the consent of the data principal under section 11 and such consent<br>has since been withdrawn; or<br>c. was made contrary to the provisions of this Act or any other law for the time being in<br>force.<br>vii. Identities of data fiduciaries: The user shall have the right to access in one place the<br>identities of the data fiduciaries with whom personal data have been shared together<br>with the categories of personal data shared with them, in such manner as may be<br>specified by regulations.<br>viii. Deceased user: The legal representative of the user has the right to request AMITA<br>to delete the data of the deceased person through a request over an email followed<br>by a postal letter, providing the legal documents to prove his\/her as the legal<br>representative and the death certificate.<\/p>\n<p>When we are processing the personal data through automated means, the user has the right<br>to<br>i. receive the following personal data in a structured, commonly used and machine-<br>readable format<br>a. the personal data provided to the data fiduciary;<br>b. the data which has been generated in the course of provision of services or use of<br>goods by the data fiduciary (AMITA); or<br>c. the data which forms part of any profile on the data principal (user), or which the data<br>fiduciary (AMITA or other associates) has otherwise obtained; and<br>ii. have the personal data referred to in clause (i) transferred to any other data fiduciary<br>in the format referred to in that clause.<br>The provisions of this above-mentioned clause shall not apply where:<br>i. processing is necessary for functions of the State or in compliance of law or order of<br>a court under section 12 of the Act;<br>ii. compliance with the request in sub-section (1) of the Act would reveal a trade secret<br>of any data fiduciary or would not be technically feasible.<br>The user has the right to requesting for his\/her information on the above-mentioned clauses<br>and shall receive clear and concise easily comprehensible information from us. The user<br>will hold regard to the purposes for which personal data is being processed. We are there to<br>help the user understand the information written on one\u2019s health record. If the user desires<br>to avail any of these rights, s\/he may send a communication to the following email ID:<br>\u2018admin@amitacare.com\u2019. Just in case we do not agree with such correction, completion,<br>updation or erasure having regard to the purposes of processing, we shall provide the user<br>with adequate justification in writing for rejecting the application. One of the reasons that we<br>will not oblige and comply with the request is where such compliance shall harm the rights<br>of any other service user.<br>In case the user is not satisfied with the justification provided by us, we will take reasonable<br>steps to indicate, alongside the relevant personal data, that the same has been disputed by<br>the user. Where we have corrected, completed, updated or erased any personal data we<br>shall also take necessary steps to notify all relevant entities or individuals to whom such<br>personal data may have been disclosed regarding the relevant correction, completion,<br>updation or erasure, particularly where such action may have an impact on user rights and<br>interests or on decisions made on the user.<br>We acknowledge the receipt of requests made on the rights of the individual. This response<br>can be expected within a short period and in alignment specified by regulations. We will<br>charge a fee if the request is not related to one\u2019s rights as may be specified under the<br>regulations of the Act. In case we refuse the user\u2019s request and s\/he are not satisfied with it,<br>s\/he have the right to file a complaint with the Authority under the Act and\/or take legal<br>remedies against the refusal within a period and manner as specified by the regulations.<br>The user can avail these services free of charge without fear of any intimidation. These<br>rights may not be absolute and may have limitations and exceptions and we will provide<br>reasons as a response email mentioning the same. We will carry out certain verifications to<br>ensure that the person availing the rights is the user or the legal representative of the user.<br>Disclosure of personal data<\/p>\n<p>We may be disclosing personal data in such situations<br>i. Enforcing any legal right or claim, seeking any relief, defending any charge, opposing<br>any claim, or obtaining any legal advice from an advocate in any impending legal<br>proceeding;<br>ii. processing of personal data by any court or tribunal in India is necessary for the<br>exercise of any judicial function;<br>iii. personal data is processed by a natural person for any personal or domestic<br>purpose, except where such processing involves disclosure to the public, or is<br>undertaken in connection with any professional or commercial activity; or<br>iv. processing of personal data is necessary for or relevant to a journalistic purpose, by<br>any person and is in compliance with any code of ethics issued by the Press Council<br>of India, or by any media self-regulatory organisation.<br>Technology used for processing<br>Technology that is currently used is for the website, for the payment gateway and for data<br>storage. We are yet to decide on the technology for processing of personal data. Whenever<br>we will be doing so, we will update it here from time to time in such manner as may be<br>specified by regulations. We will ensure that it is based on internationally accepted<br>standards and security requirements. We wish to assure the user is that we are committed<br>to setting the best international standards and safety policies, rules and technical measures<br>to protect the user\u2019s confidentiality, privacy and safety. We will make all that is possible in<br>our control to protect unauthorised entry, modification and unlawful destruction or<br>accidental loss. We implement reasonable security practices and procedures and document<br>the same considering the managerial, technical, operational and physical control measures<br>in line with the requirements of the mental health services that we manage. In spite of our<br>best efforts, there is a high likelihood of data loss or theft due to unauthorised access to the<br>user\u2019s electronic devices through which the user accesses services. At the user level, it is of<br>paramount importance that they protect themselves from unauthorised access to their<br>accounts by securing their passwords of their computers and mobile phones. The user will<br>log off from the website once the session is completed. We shall not be held liable for such<br>loss, whatsoever, caused by the user technological issues.<br>Our access and security on passwords of the personal data platform will be governed and<br>will be available with a limited group of administrative staff members. We will protect the<br>user from any unauthorised access to their information including password, mobile numbers<br>and phone numbers, such as unauthorised use of his\/her account and password.<br>Breach of any data processed<br>We will take all possible measures to ensure that the risks to breach of data is minimal or<br>absent. In situation where there is an unexpected breach of data, we will inform the<br>authority by notice and carry out actions as informed and\/or as laid in the regulations when<br>such breach is likely to cause harm to the user or to others. Our sincere effort is to ensure<br>that such circumstances do not arise. In situation where it is not possible for us to provide<br>the required information, we will reach out to the user and request them to provide the<br>required information to the Authority without undue delay. In consultation with the Authority,<br>we will report to the user on the breach of personal data and direct her\/his to take<br>appropriate remedial actions as soon as possible and post the details of the personal data<br>breach on our website.<\/p>\n<p>If and when the user is aware or has suspicion of any unauthorized use of the account, they<br>are mandated to inform AMITA as soon as possible through email and a phone call to<br>facilitate immediate action from our side and prevent any harm or loss faced by the user.<br>The contact point for sharing the information and receive support is through the email:<br>\u2018admin@amitacare.com\u2019.<br>Maintenance of records<br>We will maintain accurate and up-to-date online and\/or offline records in such form and<br>manner as may be specified by regulations, namely:<br>i. important operations in the data life-cycle including collection, transfers, and erasure<br>of personal data to demonstrate compliance as required under section 10 of the Act;<br>ii. periodic review of security safeguards under section 24 of the Act;<br>iii. data protection impact assessments under section 27 of the Act; and<br>iv. any other aspect of processing as may be specified by regulations.<br>Transfer of personal data outside India<br>In concurrence with the PDPA 2019, we may transfer anonymised sensitive personal data for<br>analysis outside India, but we will continue to store the sensitive personal data at our end.<br>When the \u2018critical personal data\u2019 that is notified by the central government is involved such<br>data will only be processed in India.<br>Cookies<br>Cookies are minuscule parts of information that are stored on user computer\u2019s hard drive by<br>companies that enable one to identify the user when the s\/he visits the site. These cookies<br>do not collect individual identification data but provide valuable statistical insights about the<br>site and the online behaviours and patterns of users, such as, date and time of visits, pages<br>viewed, the IP address including network location and computer internet address and<br>website visited. We also use \u2018persistent cookies\u2019 that identify user as unique, tailoring the<br>content to match the user\u2019s preferred interest areas. AMITA uses the temporary cookies<br>stored by the user\u2019s and service providers browser to develop an understanding of the<br>technical administration of the website, for research and development and for user<br>administration. We may do this by ourselves or use third party agencies to place or<br>recognise cookies of the user\u2019s browser.<br>By using them, we can improve the user experience and personalise online interactions; for<br>e.g., knowing the aggregate number of people who visited the website, content that is<br>popular, we can add more information on the theme. The user has a choice to disable the<br>use of cookies using his\/her browser settings; this may limit the use of some of the<br>features.<br>Some other clauses of relevance<br>i. If we have information about abuse or risk of sexual abuse to a child, we are legally<br>bound under the POCSO Act to report to the proper authorities.<br>ii. If we are aware of risk to harm user\u2019s or other people\u2019s life, we will make all efforts to<br>take action to ensure user\u2019s safety or the safety of others<br>iii. If we have orders from the Court to release personal and sensitive information, we<br>will be bound by the law to do so.<\/p>\n<p>iv. If we have to defend ourselves in the court against a complaint filed against AMITA<br>or any professional working with AMITA on matters related to the users or otherwise,<br>we will consult with our legal experts to decide on what data needs to be disclosed.<br>If the limits of privacy and confidentially are likely to be breached beyond the<br>acceptable limits, we will be informing the user on the same.<br>Grievance management on Privacy matters<br>&amp;quot;Personal data breach means any unauthorised or accidental disclosure, acquisition,<br>sharing, use, alteration, destruction of or loss of access to, personal data that compromises<br>the confidentiality, integrity or availability of personal data to a data\u201d.&nbsp; In case of any<br>personal data breach, we encourage the user to reach out to us to raise their grievance and<br>support us in assuring highest privacy. In a context where some of the clause\/s is not<br>acceptable to the user or they have a question related to it and\/or the user may decide not to<br>use the service, we request the user to reach out to the Data Protection Officer appointed by<br>AMITA under the Personal Data Protection&nbsp;Act&nbsp;2019 and seek clarification on the same. The<br>user may send in an email to \u2018admin@amitacare.com\u2019 and make a telephone call over the<br>contact number provided on the website.<br>Revisions to Privacy policy<br>We may from time to time, at our discretion, reserve the right to change, modify and\/or<br>delete some terms of the privacy policy. We are likely to make changes as and when<br>needed, and as a good practice, we will review the policy in total. The users are advised to<br>check on it regularly and we aware on the edits made on it.<br>Contact details for matters related to privacy<br>The contact details of the data fiduciary and the data protection officer are as follows:<br>Dr. Anita Rego, Director, Project AMITA, PEARLSS 4 Development<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Data and Personal Privacy Policy We, at AMITA, are committed to ensuring and protecting the personal information and dataprivacy of our visitors 1 , user of services 2 and practitioners &hellip;<\/p>\n<p class=\"read-more\"> <a class=\"\" href=\"https:\/\/amitacare.com\/index.php\/privacy-policy-3\/\"> <span class=\"screen-reader-text\">Privacy Policy<\/span> Read More &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_mi_skip_tracking":false,"footnotes":""},"class_list":["post-2828","page","type-page","status-publish","hentry"],"aioseo_notices":[],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":""},"post_excerpt_stackable":"<p>Data and Personal Privacy Policy We, at AMITA, are committed to ensuring and protecting the personal information and dataprivacy of our visitors 1 , user of services 2 and practitioners 3 on our web portal, social mediaand other forms of media. AMITA is a software application for service promoted byPEARLSS 4 Development Private Limited and this Privacy Policy applies to digital, social andsoftware applications and provided by AMITA, not just limited to this website. This PrivacyPolicy is our sincere effort to document and explain to the user, visitor and practitioner onthe manner on how we are, and the reasons for,&hellip;<\/p>\n","category_list":"","author_info":{"name":"admin","url":"https:\/\/amitacare.com\/index.php\/author\/admin\/"},"comments_num":"0 comments","_links":{"self":[{"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/pages\/2828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/comments?post=2828"}],"version-history":[{"count":13,"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/pages\/2828\/revisions"}],"predecessor-version":[{"id":2842,"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/pages\/2828\/revisions\/2842"}],"wp:attachment":[{"href":"https:\/\/amitacare.com\/index.php\/wp-json\/wp\/v2\/media?parent=2828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}